Cybersecurity Vulnerability Analyst Job at Peraton, Linthicum, MD

cUdpWEFNNWgzR2kxbEI3anFhQ0k3UXlHY1E9PQ==
  • Peraton
  • Linthicum, MD

Job Description

Program Overview

About The Role

This Cybersecurity Vulnerability Analyst supports a Vulnerability Disclosure Program (VDP) for the federal government and is responsible for reviewing and vetting security vulnerability reports submitted to the DoD VDP from outside hackers. The Analyst will evaluate the reports to ensure the vulnerability is reproducible and therefore valuable to the customer. They will assess each vulnerability for severity and assign an associated risk statement. The HackerOne Triage console tool will be utilized to assist in assigning and prioritizing reports. It will also assist the Analyst in helping identify duplicate submissions. Valid reports will be written in a DOD approved format and sent to the Vulnerability Management Analyst team for system owner coordination and mitigation. The Vulnerability Analyst will be a VDP liaison with the hacker community. 

The Vulnerability Analyst will also:

  • Utilize offensive toolsets such as Kali Linux to safely analyze production networks and systems, documenting steps and procedures to produce usable vulnerability assessments for the customer.
  • Identify and investigate vulnerabilities, asses exploit potential, and document findings and remedies for presentation to facilitate mitigations on customer systems.
  • Conduct web application vulnerability assessment testing using both automated tools and manual web exploitation techniques, using tools such as Burp Suite and open-source toolsets.
  • Utilize a variety of industry standard security tools to conduct automated scans against systems and applications.
  • Develop and execute proof-of-concept exploits to demonstrate the real-world impact of identified vulnerabilities, utilizing various web exploitation methods.

*This position requires full-time, onsite attendance Monday through Friday in the Baltimore metropolitan area.

Qualifications

Qualifications

  • Minimum Associate's degree and 5+ years of experience; Minimum Bachelor’s degree and 3+ years of experience; OR Master’s Degree and 1+ year of experience; OR 0 years with PhD. Bachelor's or Master's degree must be one of the following fields: Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering. In lieu of a degree in one of these fields, an additional 4 years of relevant experience or specialized training may be considered.
  • Strong understanding of information security principles and practices, 
  • Utilize MITRE ATT&CK, CVSS, and NIST frameworks to assess vulnerability severity and risk impact.
  • Basic understanding of web exploitation concepts and techniques.
  • Knowledge and understanding of the Open Web Application Security Project (OWASP) top 10.
  • Experience operating in a professional IT or cybersecurity environment.  
  • Experience investigating security events, threats and/or vulnerabilities. 
  • Understand information security principles, technologies and practices. 
  • Excellent customer service skills.
  • Active Security+ certification.
  • Active Secret security clearance required.

Preferred Additional Skills 

  • CEH, CCNA-Security, CySA+, OSCP (or equivalent), PenTest+ or similar certification a plus.
  • Completed multiple Hack-The-Box penetration testing labs and challenges, developing hands-on expertise in vulnerability enumeration, exploitation, privilege escalation, and post-exploitation techniques within realistic, adversarial environments.

SCA / Union / Intern Rate or Range

Details

Target Salary Range: $66,000 - $106,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at

Application Duration Statement: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. 

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Job Tags

Full time, Contract work, Temporary work, Monday to Friday, Shift work

Similar Jobs

WSP in the U.S.

UX/UI Designer Job at WSP in the U.S.

 ...Description This Opportunity WSP is currently initiating a search for a UX/UI Designer to join our Visualization Team in Meridian, ID. The following location will also be considered: Remote (United States) . This position is approved for remote work within the... 

Reflection Dental

Dental Assistant (+2 years experience) Job at Reflection Dental

 ...Team-Driven Environment. Are you a skilled Dental Assistant looking for a supportive, no-drama environment where your experience is valued and your voice matters? We're a...  ...do best. Position Details: Full-time or Part-time (flexible for the right candidate)... 

Sago

UX Designer Job at Sago

 ...collaboration, creativity, and personal growth, we're looking for a UX Designer ready to join us in making a real impact. As a global...  ...or as part of a team ~ Track record of successful remote work Benefits We are a remote-first company Health... 

Audacy

Virtual Assistant/Administrative Assistant(Remote) Job at Audacy

 ...We are seeking a highly organized and detail-oriented Virtual Assistant / Administrative Assistant to support daily business operations...  ...discretion and confidentiality~Reliable internet connection (for remote roles)Preferred Skills~Experience with CRM systems~... 

Erico Technologies LLC

Virtual Assistant (Remote - United States) Job at Erico Technologies LLC

 ...Virtual Assistant (Remote United States) Job Type: Part-Time Location: Remote (United States only) Pay: $22$28 per hour (based on experience) About the Role Erico Technologies LLC is seeking a reliable and detail-oriented Virtual Assistant...